CVE-2008-2999: SQL Injection
Published Jul 3, 2008
·Updated
Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
15 affected components
Drupal Drupal=5.4
Drupal Aggregation module=3.2
Drupal Drupal=5.2
Drupal Drupal=5.7
Drupal Drupal=5.1_rev1.1
Drupal Drupal=5.0
Drupal Aggregation module=4.0
Drupal Aggregation module=4.1
Drupal Aggregation module=4.3
Drupal Aggregation module=4.2
Drupal Drupal=5.1
Drupal Drupal=5.3
Drupal Aggregation module=3.1
Drupal Drupal=5.5.
Drupal Aggregation module=3.0
Remediation
Patch Available
Event History
Jul 3, 2008
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2999?
CVE-2008-2999 is classified as a critical severity vulnerability.
2
How do I fix CVE-2008-2999?
To fix CVE-2008-2999, update the Drupal Aggregation module to a version that is not affected by this vulnerability.
3
Which versions of Drupal are affected by CVE-2008-2999?
Drupal versions 5.0 to 5.7 are affected by CVE-2008-2999.
4
What kind of attacks can exploit CVE-2008-2999?
CVE-2008-2999 allows remote attackers to execute arbitrary SQL commands, leading to potential database compromise.
5
Is CVE-2008-2999 specific to any modules in Drupal?
Yes, CVE-2008-2999 specifically impacts the Aggregation module version 5.x before 5.x-4.4.